Posted on Tuesday, April 17th, 2007 | Bookmark on del.icio.us

Nirbot’s Latest Move: MS DNS Exploits

by Jose Nazario

The latest turn in the Nirbot saga is that they’ve gone and incorporated the MS Windows DNS RPC interface exploit into their bot. We started seeing this in ATLAS starting Sunday evening GMT and it appears that this flood of MS DNS RPC exploits was seeded into an existing botnet. It appears that one of the public exploits was rolled into the bot over the weekend.

nirbot_ms_dns_exploits

Here’s some C&C information for you:

I’m not going to share passwords or any other specific information with you at this time. The malware on the bots has been updated as they join the channel. Signs of infections include connections to hosts with that hostname on that port, scans on TCP port 1025 (and other exploits in the bot include SYMC06-010, MS06-040, and weak passwords).

Links around the net on this topic include:

Popularity: 1% [?]

3 Responses | Add your own



Comment Post by: www.andrewhay.ca » Suggested Blog Reading - Tuesday April 17th, 2007 — April 17th, 2007 @ 11:47 am EST  Reply

[...] Nirbot’s Latest Move: MS DNS Exploits The latest turn in the Nirbot saga is that they’ve gone and incorporated the MS Windows DNS RPC interface exploit into their bot. We started seeing this in ATLAS starting Sunday evening GMT and it appears that this flood of MS DNS RPC exploits was seeded into an existing botnet. It appears that one of the public exploits was rolled into the bot over the weekend. [...]

Comment Post by: Nirbot actively exploiting the DNS RPC vulnerability at Security Samizdat — April 17th, 2007 @ 3:50 pm EST  Reply

[...] According to Arbor Networks: The latest turn in the Nirbot saga is that they’ve gone and incorporated the MS Windows DNS RPC interface exploit into their bot. We started seeing this in ATLAS starting Sunday evening GMT and it appears that this flood of MS DNS RPC exploits was seeded into an existing botnet. It appears that one of the public exploits was rolled into the bot over the weekend. [...]

Comment Post by: Nirbot Neutered? · Security to the Core | Arbor Networks Security Blog — April 23rd, 2007 @ 10:53 am EST  Reply

[...] Nirbot – Even Botters Need AttentionNirbot’s Latest Move: MS DNS Exploits [...]

Leave a Comment